THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8vh3-g2qg-2h2c (critical) — nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

[GHSA] GHSA-8vh3-g2qg-2h2c (critical) — nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

medgithub_advisoriesPublished 2026-08-25

GHSA-8vh3-g2qg-2h2c Severity: critical CVE: CVE-2026-55640

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

## Summary The `POST /webhooks/nextcloud` endpoint has no authentication by default: `WEBHOOK_SECRET` defaults to `None` and is never required by startup validation. When unset, the receiver ac

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8vh3-g2qg-2h2c